fix(housekeeping): harden command dispatch boundaries

This commit is contained in:
Simo committed 2026-08-27 19:32:19 +02:00
1 parent 796d009c07
commit 00618fb2a3
8 files changed
+608 -30

No files matched your search

+29 -1
View File
@@ -1,6 +1,21 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
import { z } from "zod";
import { registerHousekeepingCommand } from "@/features/housekeeping/foundation/commands/registry";
vi.mock(
"@/features/housekeeping/foundation/commands/registry",
async (importOriginal) => ({
...(await importOriginal<
typeof import("@/features/housekeeping/foundation/commands/registry")
>()),
sealHousekeepingCommandRegistry: sealRegistryMock,
}),
);
vi.mock("@/features/housekeeping/foundation/commands/bootstrap", () => ({
housekeepingCommandRegistryReady: true,
}));
import {
anyCapability,
ok,
@@ -15,6 +30,7 @@ const {
getContextMock,
getIpMock,
rateLimitCalls,
sealRegistryMock,
} = vi.hoisted(() => ({
auditEntries: [] as AuditEntry[],
auditWriteMock: vi.fn(),
@@ -30,6 +46,7 @@ const {
getContextMock: vi.fn(),
getIpMock: vi.fn(),
rateLimitCalls: [] as Array<[string, number, number]>,
sealRegistryMock: vi.fn(),
}));
vi.mock("@/features/housekeeping/foundation/server-capability-context", () => ({
@@ -77,6 +94,7 @@ beforeEach(() => {
rateLimitCalls.length = 0;
getContextMock.mockReset().mockResolvedValue(context);
getIpMock.mockReset().mockResolvedValue("203.0.113.7");
sealRegistryMock.mockReset();
auditWriteMock.mockReset().mockImplementation(async (entry: AuditEntry) => {
auditEntries.push({ ...entry });
});
@@ -115,6 +133,7 @@ describe("executeHousekeepingCommand", () => {
},
]);
expect(auditEntries[0]?.correlationId).toBe(result.correlationId);
expect(sealRegistryMock).not.toHaveBeenCalled();
});
it("strictly rejects spoofed server-owned metadata before execution", async () => {
@@ -136,7 +155,16 @@ describe("executeHousekeepingCommand", () => {
});
expect(commandExecutions).toEqual([]);
expect(rateLimitCalls).toEqual([]);
expect(auditEntries).toEqual([]);
expect(auditEntries).toMatchObject([
{
userId: 71,
action: "housekeeping.command.dispatch",
target: "request-envelope",
ipAddress: "203.0.113.7",
outcome: "denied",
},
]);
expect(JSON.stringify(auditEntries)).not.toContain("forged");
});
it("sanitizes server context acquisition failures into typed results", async () => {
+1 -2
View File
@@ -1,8 +1,8 @@
"use server";
import "@/features/housekeeping/foundation/commands/bootstrap";
import { AuditOutcomePersistenceError } from "@/features/housekeeping/foundation/commands/audit-envelope";
import { dispatchHousekeepingCommand } from "@/features/housekeeping/foundation/commands/dispatcher";
import { sealHousekeepingCommandRegistry } from "@/features/housekeeping/foundation/commands/registry";
import {
fail,
type HousekeepingResult,
@@ -15,7 +15,6 @@ import { housekeepingAuditWriter } from "@/lib/services/audit";
export async function executeHousekeepingCommand(
request: unknown,
): Promise<HousekeepingResult<unknown>> {
sealHousekeepingCommandRegistry();
try {
const [context, ipAddress] = await Promise.all([
getHousekeepingCapabilityContext(),